VirtueMart 3.8.6 comes to address a new Cross-site Scripting (XSS) security vulnerability caused by the manufactuer dropdown which was found by 4N_CURZE.
Important Note: As announced before, Joomla 3.7.1 with security fix is out. You're strongly recommended to update your sites immediately.
The Joomla! Security Strike Team (JSST) has been informed of a critical security issue in the Joomla! core that you are highly recommended to update your Joomla installation after the security release of Joomla 3.7.1 on Wednesday, 17th May.
You're highly recommended to update your site with Joomla 3.4.6. This Joomla release addresses a critical security vulnerability and 4 low level security vulnerabilities that affects all versions from 1.5 to 3.4 without any other changes compared to Joomla 3.4.5.